vir z prilohy z exekucniho emailu
Napsal: 19 črc 2014 14:29
Logfile of random's system information tool 1.10 (written by random/random)
Run by yourfragged at 2014-07-19 15:19:20
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 238 GB (50%) free of 477 GB
Total RAM: 2047 MB (31% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:19:32, on 19.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.18487)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\yourfragged.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=1198 ... 304F50CB37
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Virtuální klávesnice - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Služba Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - Unknown owner - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (file missing)
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - Unknown owner - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6812 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe" -r
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe" -hidden /prefetch:1
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3260.0.401841937\963891756" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,15,39 --gpu-vendor-id=0x10de --gpu-device-id=0x05e2 --gpu-driver-vendor=NVIDIA --gpu-driver-version=8.17.12.8562 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group13 pct:1d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_63/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="3260.2.533039153\15912006" /prefetch:673131151
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group13 pct:1d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_63/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="3260.21.1954057033\115933754" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group13 pct:1d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_63/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="3260.71.1136274217\427534699" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group13 pct:1d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_63/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="3260.73.1297754373\1238933648" /prefetch:673131151
"C:\Users\yourfragged\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore1cec718c94750c.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\RDReminder.job - C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe -rem
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-07-17 800448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-07-17 1499968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}]
Safe Money Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-07-17 550080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-07-17 996544]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-07-17 655040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-07-17 1238336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-07-04 463272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}]
Safe Money Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-07-17 455360]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-07-04 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-07-17 798912]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-11-20 13662936]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-05-30 1279480]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7]
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe /Auto []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe /min []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Avira Systray]
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Programy\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorShield]
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2014-05-14 2774936]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdater]
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2014-05-14 3681688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.RTV1"=rtvcvfw64.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-07-19 15:19:22 ----D---- C:\Program Files\trend micro
2014-07-19 15:19:20 ----D---- C:\rsit
2014-07-18 00:22:10 ----A---- C:\Windows\system32\_ HD PORNO _ Jewels Jade 02 ( brunetky anal mlib porno film brazzers teen best hardcore erotic porn oral nice ass young girls holky with old busty woman new akce sukani of girl milf xxx sex erot.lnk
2014-07-18 00:21:48 ----A---- C:\Windows\system32\_ HD PORNO _ Nikita von James ( blondynky psp porno film brazzers teen best hardcore erotic porn oral nice ass young girls holky with old busty woman new akce sukani of girl milf xxx sex erotika.lnk
2014-07-17 22:07:18 ----A---- C:\Windows\system32\klfphc.dll
2014-07-17 22:06:12 ----D---- C:\Windows\ELAMBKUP
2014-07-17 22:05:58 ----D---- C:\ProgramData\Kaspersky Lab
2014-07-17 22:05:58 ----D---- C:\Program Files (x86)\Kaspersky Lab
2014-07-17 22:05:38 ----A---- C:\Windows\system32\drivers\klif.sys
2014-07-17 22:05:38 ----A---- C:\Windows\system32\drivers\klflt.sys
2014-07-17 16:56:26 ----A---- C:\Windows\system32\drivers\stflt.sys
2014-07-17 16:56:23 ----D---- C:\Users\yourfragged\AppData\Roaming\Spyware Terminator
2014-07-17 16:56:23 ----D---- C:\ProgramData\Spyware Terminator
2014-07-17 16:55:58 ----D---- C:\Program Files (x86)\Spyware Terminator
2014-07-17 15:52:49 ----D---- C:\ProgramData\NVIDIA
2014-07-17 15:50:50 ----A---- C:\Windows\system32\easyupdatusapiu64.dll
2014-07-17 15:49:44 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2014-07-17 15:49:44 ----A---- C:\Windows\system32\OpenCL.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvwgf2umx.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvoglv64.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvgenco64.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvdispco64.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvd3dumx.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvcuvid.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvcuvenc.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvcuda.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvcompiler.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvapi64.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2014-07-17 15:46:58 ----D---- C:\ProgramData\NVIDIA Corporation
2014-07-17 15:46:55 ----D---- C:\Program Files\NVIDIA Corporation
2014-07-17 15:41:22 ----A---- C:\Windows\system32\nvvsvc.exe
2014-07-17 15:41:22 ----A---- C:\Windows\system32\nvsvc64.dll
2014-07-17 15:41:22 ----A---- C:\Windows\system32\nvshext.dll
2014-07-17 15:41:22 ----A---- C:\Windows\system32\nvmctray.dll
2014-07-17 15:41:22 ----A---- C:\Windows\system32\nvcpl.dll
2014-07-17 15:16:19 ----D---- C:\Windows\DEA314C409294250BC9298E4C105F28D.TMP
2014-07-17 15:09:36 ----A---- C:\Windows\system32\dpinst.exe
2014-07-17 15:09:32 ----A---- C:\Windows\SYSWOW64\nvdecodemft.dll
2014-07-17 15:09:24 ----D---- C:\NVIDIA
2014-07-17 13:10:55 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2014-07-17 13:00:36 ----D---- C:\Program Files (x86)\Avira
2014-07-17 12:32:55 ----D---- C:\Users\yourfragged\AppData\Roaming\AdobeChk
2014-07-16 23:45:34 ----A---- C:\Windows\ntbtlog.txt
2014-07-16 21:03:49 ----D---- C:\Windows\B9DB4C7601A446D58910F7AA6376DBAF.TMP
2014-07-16 20:57:14 ----A---- C:\Windows\system32\nvgenco642040.dll
2014-07-16 20:57:14 ----A---- C:\Windows\system32\nvdispco642090.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\wdigest.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\TSpkg.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\schannel.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\ncrypt.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\msv1_0.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\kerberos.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\credssp.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\url.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\mshta.exe
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\wininet.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\urlmon.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\url.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\mshtml.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\mshta.exe
2014-07-16 19:33:12 ----A---- C:\Windows\system32\msfeedssync.exe
2014-07-16 19:33:12 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\jsproxy.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\ieUnatt.exe
2014-07-16 19:33:12 ----A---- C:\Windows\system32\ieui.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\iertutil.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\ieframe.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-16 19:31:54 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-07-16 19:31:54 ----A---- C:\Windows\system32\win32k.sys
2014-07-16 19:31:54 ----A---- C:\Windows\system32\osk.exe
2014-07-16 19:31:06 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-07-16 19:31:06 ----A---- C:\Windows\system32\qedit.dll
2014-07-16 19:29:55 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-16 19:29:18 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-07-16 19:29:18 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-07-16 19:29:18 ----A---- C:\Windows\system32\lsasrv.dll
2014-07-16 19:28:29 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-07-16 19:28:29 ----A---- C:\Windows\system32\rdpcorets.dll
2014-07-16 19:27:49 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-07-16 19:27:49 ----A---- C:\Windows\system32\usp10.dll
2014-07-16 19:26:39 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2014-07-16 19:26:39 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-07-16 19:26:39 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-07-16 19:26:39 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-07-16 19:26:39 ----A---- C:\Windows\system32\msxml6r.dll
2014-07-16 19:26:39 ----A---- C:\Windows\system32\msxml6.dll
2014-07-16 19:26:39 ----A---- C:\Windows\system32\msxml3r.dll
2014-07-16 19:26:39 ----A---- C:\Windows\system32\msxml3.dll
2014-07-16 19:25:59 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-07-16 19:25:59 ----A---- C:\Windows\system32\drivers\netio.sys
2014-07-16 19:25:59 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-07-16 19:24:15 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-07-16 19:24:14 ----A---- C:\Windows\system32\shell32.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\winlogon.exe
2014-07-16 19:22:39 ----A---- C:\Windows\system32\wincredprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\sspisrv.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\sspicli.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\secur32.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\objsel.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-07-16 19:22:39 ----A---- C:\Windows\system32\lsass.exe
2014-07-16 19:22:39 ----A---- C:\Windows\system32\KernelBase.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-07-16 19:22:39 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-07-16 19:22:39 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\dimsroam.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\cngprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\capiprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\adprovider.dll
2014-07-16 19:22:38 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-07-16 19:22:38 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-07-16 19:21:34 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-07-16 19:21:13 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2014-07-16 19:21:13 ----A---- C:\Windows\system32\iologmsg.dll
2014-07-16 19:21:13 ----A---- C:\Windows\system32\drivers\storport.sys
2014-07-16 19:21:13 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2014-07-16 19:21:13 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\wow32.dll
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\user.exe
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\setup16.exe
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\instnm.exe
2014-07-16 19:20:50 ----A---- C:\Windows\system32\wow64win.dll
2014-07-16 19:20:50 ----A---- C:\Windows\system32\wow64cpu.dll
2014-07-16 19:20:50 ----A---- C:\Windows\system32\wow64.dll
2014-07-16 19:20:50 ----A---- C:\Windows\system32\ntvdm64.dll
2014-07-16 19:20:50 ----A---- C:\Windows\system32\kernel32.dll
2014-07-16 19:20:32 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-07-16 19:20:32 ----A---- C:\Windows\system32\wer.dll
2014-07-16 19:20:19 ----A---- C:\Windows\system32\wwansvc.dll
2014-07-16 19:17:14 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-07-16 19:17:14 ----A---- C:\Windows\system32\vbscript.dll
2014-07-16 19:15:26 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-07-16 19:15:26 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-07-16 19:15:26 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-07-16 19:15:26 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-07-16 19:15:26 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-07-16 19:15:26 ----A---- C:\Windows\system32\msdrm.dll
2014-07-16 19:15:25 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-07-16 19:15:25 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-07-16 19:15:25 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-07-16 19:15:25 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-07-16 19:15:25 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-07-16 19:15:25 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-07-16 19:15:25 ----A---- C:\Windows\system32\secproc_isv.dll
2014-07-16 19:15:25 ----A---- C:\Windows\system32\secproc.dll
2014-07-16 19:15:25 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-07-16 19:15:25 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-07-16 19:15:25 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-07-16 19:15:25 ----A---- C:\Windows\system32\RMActivate.exe
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbport.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbohci.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbhub.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbehci.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbd.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2014-07-16 19:14:41 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2014-07-16 19:14:41 ----A---- C:\Windows\system32\msieftp.dll
2014-07-16 19:14:27 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2014-07-16 19:14:27 ----A---- C:\Windows\SYSWOW64\wmp.dll
2014-07-16 19:14:27 ----A---- C:\Windows\system32\wmploc.DLL
2014-07-16 19:14:27 ----A---- C:\Windows\system32\wmp.dll
2014-07-16 19:14:07 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-07-16 19:14:07 ----A---- C:\Windows\system32\tzres.dll
2014-07-16 19:13:49 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-07-16 19:13:49 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-07-16 19:13:49 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-07-16 19:13:49 ----A---- C:\Windows\system32\wscript.exe
2014-07-16 19:13:49 ----A---- C:\Windows\system32\scrrun.dll
2014-07-16 19:13:49 ----A---- C:\Windows\system32\cscript.exe
2014-07-16 19:13:40 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-07-16 19:13:40 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-07-16 19:13:32 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-07-16 19:13:32 ----A---- C:\Windows\system32\imagehlp.dll
2014-07-16 19:13:23 ----A---- C:\Windows\SYSWOW64\explorer.exe
2014-07-16 19:13:23 ----A---- C:\Windows\explorer.exe
2014-07-16 19:13:11 ----A---- C:\Windows\system32\spoolsv.exe
2014-07-16 19:13:11 ----A---- C:\Windows\splwow64.exe
2014-07-16 19:12:45 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2014-07-16 19:12:45 ----A---- C:\Windows\SYSWOW64\esent.dll
2014-07-16 19:12:45 ----A---- C:\Windows\system32\fsutil.exe
2014-07-16 19:12:45 ----A---- C:\Windows\system32\esent.dll
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\nvstor.sys
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\nvraid.sys
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\amdxata.sys
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\amdsata.sys
2014-07-16 19:06:52 ----D---- C:\Users\yourfragged\AppData\Roaming\ProductData
2014-07-16 11:52:58 ----D---- C:\ProgramData\Riot Games
2014-07-16 00:35:57 ----A---- C:\Windows\system32\nvspbridge64.dll
2014-07-16 00:35:56 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-07-16 00:35:25 ----D---- C:\Program Files (x86)\AGEIA Technologies
2014-07-16 00:26:53 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2014-07-16 00:26:53 ----A---- C:\Windows\system32\nvaudcap64v.dll
2014-07-16 00:26:53 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2014-07-16 00:26:49 ----A---- C:\Windows\system32\nvdispgenco6434043.dll
2014-07-16 00:26:49 ----A---- C:\Windows\system32\nvdispco6434043.dll
2014-07-16 00:26:48 ----A---- C:\Windows\system32\nvopencl.dll
2014-07-16 00:26:48 ----A---- C:\Windows\system32\NvFBC64.dll
2014-07-16 00:26:47 ----A---- C:\Windows\SYSWOW64\SET1DF4.tmp
2014-07-16 00:26:47 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2014-07-16 00:26:47 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2014-07-16 00:26:47 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2014-07-16 00:26:47 ----A---- C:\Windows\system32\NvIFR64.dll
2014-07-15 22:22:46 ----A---- C:\Windows\system32\drivers\atksgt.sys
2014-07-15 22:22:45 ----A---- C:\Windows\system32\drivers\lirsgt.sys
2014-06-25 00:47:09 ----A---- C:\Windows\_ HD PORNO _ Jewels Jade 02 ( brunetky anal mlib porno film brazzers teen best hardcore erotic porn oral nice ass young girls holky with old busty woman new akce sukani of girl milf xxx sex erot.lnk
2014-06-25 00:46:10 ----A---- C:\Windows\_ HD PORNO _ Nikita von James ( blondynky psp porno film brazzers teen best hardcore erotic porn oral nice ass young girls holky with old busty woman new akce sukani of girl milf xxx sex erotika.lnk
======List of files/folders modified in the last 1 month======
2014-07-19 15:19:32 ----D---- C:\Windows\Prefetch
2014-07-19 15:19:27 ----D---- C:\Windows\Temp
2014-07-19 15:19:22 ----RD---- C:\Program Files
2014-07-19 12:08:43 ----SHD---- C:\System Volume Information
2014-07-18 00:22:10 ----D---- C:\Windows\System32
2014-07-18 00:16:43 ----D---- C:\Windows\Tasks
2014-07-17 22:36:14 ----SHD---- C:\Windows\Installer
2014-07-17 22:35:36 ----D---- C:\Windows\system32\drivers
2014-07-17 22:07:19 ----D---- C:\Windows\system32\catroot
2014-07-17 22:07:11 ----D---- C:\Windows\inf
2014-07-17 22:07:05 ----D---- C:\Windows\system32\DriverStore
2014-07-17 22:06:12 ----D---- C:\Windows
2014-07-17 22:05:58 ----RD---- C:\Program Files (x86)
2014-07-17 22:05:58 ----HD---- C:\ProgramData
2014-07-17 22:04:29 ----D---- C:\ProgramData\Package Cache
2014-07-17 22:04:25 ----D---- C:\Windows\SysWOW64
2014-07-17 21:52:40 ----D---- C:\ProgramData\Razer
2014-07-17 21:52:40 ----D---- C:\Program Files (x86)\Razer
2014-07-17 21:51:37 ----D---- C:\Program Files (x86)\IObit
2014-07-17 21:22:12 ----D---- C:\ProgramData\ccoonntoinuUEtossavea
2014-07-17 19:11:48 ----D---- C:\Windows\system32\config
2014-07-17 15:41:21 ----D---- C:\Windows\Help
2014-07-17 15:15:51 ----D---- C:\Windows\system32\catroot2
2014-07-17 14:48:59 ----D---- C:\Windows\system32\wfp
2014-07-17 14:48:57 ----D---- C:\Windows\system32\wbem
2014-07-17 14:47:59 ----D---- C:\Windows\system32\NDF
2014-07-17 14:47:58 ----D---- C:\Windows\system32\CodeIntegrity
2014-07-17 14:47:58 ----D---- C:\Windows\security
2014-07-17 14:47:58 ----D---- C:\Progamy
2014-07-17 14:47:54 ----D---- C:\Windows\registration
2014-07-17 14:47:04 ----RD---- C:\Users
2014-07-16 23:05:32 ----D---- C:\Windows\Microsoft.NET
2014-07-16 23:05:02 ----RSD---- C:\Windows\assembly
2014-07-16 22:14:42 ----D---- C:\Game
2014-07-16 22:03:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-16 21:49:49 ----D---- C:\Windows\winsxs
2014-07-16 21:35:59 ----D---- C:\Windows\SYSWOW64\Dism
2014-07-16 21:35:59 ----D---- C:\Windows\system32\Dism
2014-07-16 21:35:59 ----D---- C:\Windows\system32\cs-CZ
2014-07-16 21:35:58 ----D---- C:\Windows\SYSWOW64\migration
2014-07-16 21:35:58 ----D---- C:\Windows\system32\migration
2014-07-16 21:35:58 ----D---- C:\Program Files\Internet Explorer
2014-07-16 21:35:58 ----D---- C:\Program Files (x86)\Internet Explorer
2014-07-16 21:35:57 ----D---- C:\Windows\ehome
2014-07-16 21:35:57 ----D---- C:\Program Files\Windows Journal
2014-07-16 21:35:53 ----D---- C:\Windows\PolicyDefinitions
2014-07-16 21:35:52 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-07-16 21:35:51 ----D---- C:\Windows\AppPatch
2014-07-16 21:35:49 ----D---- C:\Program Files\Windows Media Player
2014-07-16 21:35:49 ----D---- C:\Program Files (x86)\Windows Media Player
2014-07-16 19:16:45 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-07-16 19:11:25 ----D---- C:\Windows\Logs
2014-07-16 19:11:24 ----D---- C:\Users\yourfragged\AppData\Roaming\DAEMON Tools Lite
2014-07-16 19:07:31 ----D---- C:\Users\yourfragged\AppData\Roaming\uTorrent
2014-07-16 19:02:07 ----D---- C:\Programy
2014-07-16 19:00:13 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-07-15 22:01:18 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2014-07-17 458336]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2013-05-22 17720]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-04-07 283200]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2014-07-17 625248]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2013-10-20 29792]
R1 klpd;klpd; C:\Windows\system32\DRIVERS\klpd.sys [2013-04-12 15456]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2013-05-14 55904]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2014-07-17 178272]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2014-07-15 43168]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\Windows\system32\DRIVERS\stflt.sys [2014-07-17 51496]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-12-30 3760344]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2014-07-17 29280]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2013-10-20 29280]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-03-31 40392]
R3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver; C:\Windows\system32\DRIVERS\Rtnic64.sys [2009-06-10 51712]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-11-20 883928]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2014-07-15 310728]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Progamy\Garena Plus\Room\safedrv.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 Razerlow;Razer Pro|Solutions; C:\Windows\system32\drivers\Razerlow.sys [2013-11-20 11136]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2013-11-19 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2013-11-19 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-11-19 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2013-11-19 30208]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S4 klflt;klflt; C:\Windows\system32\DRIVERS\klflt.sys [2014-07-17 115296]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AVP;Služba Kaspersky Anti-Virus; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [2013-10-20 214512]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-10-15 1640768]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2014-05-14 1146304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2014-05-04 2152736]
S2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe []
S2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-11-19 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-07 116648]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-07 116648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
Run by yourfragged at 2014-07-19 15:19:20
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 238 GB (50%) free of 477 GB
Total RAM: 2047 MB (31% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:19:32, on 19.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.18487)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\yourfragged.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=1198 ... 304F50CB37
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Virtuální klávesnice - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Služba Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - Unknown owner - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (file missing)
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - Unknown owner - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6812 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe" -r
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe" -hidden /prefetch:1
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3260.0.401841937\963891756" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,15,39 --gpu-vendor-id=0x10de --gpu-device-id=0x05e2 --gpu-driver-vendor=NVIDIA --gpu-driver-version=8.17.12.8562 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group13 pct:1d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_63/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="3260.2.533039153\15912006" /prefetch:673131151
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group13 pct:1d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_63/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="3260.21.1954057033\115933754" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group13 pct:1d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_63/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="3260.71.1136274217\427534699" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group13 pct:1d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_63/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="3260.73.1297754373\1238933648" /prefetch:673131151
"C:\Users\yourfragged\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore1cec718c94750c.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\RDReminder.job - C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe -rem
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-07-17 800448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-07-17 1499968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}]
Safe Money Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-07-17 550080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-07-17 996544]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-07-17 655040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-07-17 1238336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-07-04 463272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}]
Safe Money Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-07-17 455360]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-07-04 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-07-17 798912]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-11-20 13662936]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-05-30 1279480]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7]
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe /Auto []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe /min []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Avira Systray]
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Programy\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorShield]
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2014-05-14 2774936]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdater]
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2014-05-14 3681688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.RTV1"=rtvcvfw64.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-07-19 15:19:22 ----D---- C:\Program Files\trend micro
2014-07-19 15:19:20 ----D---- C:\rsit
2014-07-18 00:22:10 ----A---- C:\Windows\system32\_ HD PORNO _ Jewels Jade 02 ( brunetky anal mlib porno film brazzers teen best hardcore erotic porn oral nice ass young girls holky with old busty woman new akce sukani of girl milf xxx sex erot.lnk
2014-07-18 00:21:48 ----A---- C:\Windows\system32\_ HD PORNO _ Nikita von James ( blondynky psp porno film brazzers teen best hardcore erotic porn oral nice ass young girls holky with old busty woman new akce sukani of girl milf xxx sex erotika.lnk
2014-07-17 22:07:18 ----A---- C:\Windows\system32\klfphc.dll
2014-07-17 22:06:12 ----D---- C:\Windows\ELAMBKUP
2014-07-17 22:05:58 ----D---- C:\ProgramData\Kaspersky Lab
2014-07-17 22:05:58 ----D---- C:\Program Files (x86)\Kaspersky Lab
2014-07-17 22:05:38 ----A---- C:\Windows\system32\drivers\klif.sys
2014-07-17 22:05:38 ----A---- C:\Windows\system32\drivers\klflt.sys
2014-07-17 16:56:26 ----A---- C:\Windows\system32\drivers\stflt.sys
2014-07-17 16:56:23 ----D---- C:\Users\yourfragged\AppData\Roaming\Spyware Terminator
2014-07-17 16:56:23 ----D---- C:\ProgramData\Spyware Terminator
2014-07-17 16:55:58 ----D---- C:\Program Files (x86)\Spyware Terminator
2014-07-17 15:52:49 ----D---- C:\ProgramData\NVIDIA
2014-07-17 15:50:50 ----A---- C:\Windows\system32\easyupdatusapiu64.dll
2014-07-17 15:49:44 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2014-07-17 15:49:44 ----A---- C:\Windows\system32\OpenCL.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2014-07-17 15:49:43 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvwgf2umx.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvoglv64.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvgenco64.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvdispco64.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvd3dumx.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvcuvid.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvcuvenc.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvcuda.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvcompiler.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\nvapi64.dll
2014-07-17 15:49:43 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2014-07-17 15:46:58 ----D---- C:\ProgramData\NVIDIA Corporation
2014-07-17 15:46:55 ----D---- C:\Program Files\NVIDIA Corporation
2014-07-17 15:41:22 ----A---- C:\Windows\system32\nvvsvc.exe
2014-07-17 15:41:22 ----A---- C:\Windows\system32\nvsvc64.dll
2014-07-17 15:41:22 ----A---- C:\Windows\system32\nvshext.dll
2014-07-17 15:41:22 ----A---- C:\Windows\system32\nvmctray.dll
2014-07-17 15:41:22 ----A---- C:\Windows\system32\nvcpl.dll
2014-07-17 15:16:19 ----D---- C:\Windows\DEA314C409294250BC9298E4C105F28D.TMP
2014-07-17 15:09:36 ----A---- C:\Windows\system32\dpinst.exe
2014-07-17 15:09:32 ----A---- C:\Windows\SYSWOW64\nvdecodemft.dll
2014-07-17 15:09:24 ----D---- C:\NVIDIA
2014-07-17 13:10:55 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2014-07-17 13:00:36 ----D---- C:\Program Files (x86)\Avira
2014-07-17 12:32:55 ----D---- C:\Users\yourfragged\AppData\Roaming\AdobeChk
2014-07-16 23:45:34 ----A---- C:\Windows\ntbtlog.txt
2014-07-16 21:03:49 ----D---- C:\Windows\B9DB4C7601A446D58910F7AA6376DBAF.TMP
2014-07-16 20:57:14 ----A---- C:\Windows\system32\nvgenco642040.dll
2014-07-16 20:57:14 ----A---- C:\Windows\system32\nvdispco642090.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-07-16 19:35:29 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\wdigest.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\TSpkg.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\schannel.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\ncrypt.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\msv1_0.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\kerberos.dll
2014-07-16 19:35:29 ----A---- C:\Windows\system32\credssp.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\url.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\mshta.exe
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-07-16 19:33:12 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\wininet.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\urlmon.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\url.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\mshtml.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\mshta.exe
2014-07-16 19:33:12 ----A---- C:\Windows\system32\msfeedssync.exe
2014-07-16 19:33:12 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\jsproxy.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\ieUnatt.exe
2014-07-16 19:33:12 ----A---- C:\Windows\system32\ieui.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\iertutil.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\ieframe.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-16 19:33:12 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-16 19:31:54 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-07-16 19:31:54 ----A---- C:\Windows\system32\win32k.sys
2014-07-16 19:31:54 ----A---- C:\Windows\system32\osk.exe
2014-07-16 19:31:06 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-07-16 19:31:06 ----A---- C:\Windows\system32\qedit.dll
2014-07-16 19:29:55 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-16 19:29:18 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-07-16 19:29:18 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-07-16 19:29:18 ----A---- C:\Windows\system32\lsasrv.dll
2014-07-16 19:28:29 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-07-16 19:28:29 ----A---- C:\Windows\system32\rdpcorets.dll
2014-07-16 19:27:49 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-07-16 19:27:49 ----A---- C:\Windows\system32\usp10.dll
2014-07-16 19:26:39 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2014-07-16 19:26:39 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-07-16 19:26:39 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-07-16 19:26:39 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-07-16 19:26:39 ----A---- C:\Windows\system32\msxml6r.dll
2014-07-16 19:26:39 ----A---- C:\Windows\system32\msxml6.dll
2014-07-16 19:26:39 ----A---- C:\Windows\system32\msxml3r.dll
2014-07-16 19:26:39 ----A---- C:\Windows\system32\msxml3.dll
2014-07-16 19:25:59 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-07-16 19:25:59 ----A---- C:\Windows\system32\drivers\netio.sys
2014-07-16 19:25:59 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-07-16 19:24:15 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-07-16 19:24:14 ----A---- C:\Windows\system32\shell32.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\winlogon.exe
2014-07-16 19:22:39 ----A---- C:\Windows\system32\wincredprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\sspisrv.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\sspicli.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\secur32.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\objsel.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-07-16 19:22:39 ----A---- C:\Windows\system32\lsass.exe
2014-07-16 19:22:39 ----A---- C:\Windows\system32\KernelBase.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-07-16 19:22:39 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-07-16 19:22:39 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\dimsroam.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\cngprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\capiprovider.dll
2014-07-16 19:22:39 ----A---- C:\Windows\system32\adprovider.dll
2014-07-16 19:22:38 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-07-16 19:22:38 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-07-16 19:21:34 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-07-16 19:21:13 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2014-07-16 19:21:13 ----A---- C:\Windows\system32\iologmsg.dll
2014-07-16 19:21:13 ----A---- C:\Windows\system32\drivers\storport.sys
2014-07-16 19:21:13 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2014-07-16 19:21:13 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\wow32.dll
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\user.exe
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\setup16.exe
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-07-16 19:20:50 ----A---- C:\Windows\SYSWOW64\instnm.exe
2014-07-16 19:20:50 ----A---- C:\Windows\system32\wow64win.dll
2014-07-16 19:20:50 ----A---- C:\Windows\system32\wow64cpu.dll
2014-07-16 19:20:50 ----A---- C:\Windows\system32\wow64.dll
2014-07-16 19:20:50 ----A---- C:\Windows\system32\ntvdm64.dll
2014-07-16 19:20:50 ----A---- C:\Windows\system32\kernel32.dll
2014-07-16 19:20:32 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-07-16 19:20:32 ----A---- C:\Windows\system32\wer.dll
2014-07-16 19:20:19 ----A---- C:\Windows\system32\wwansvc.dll
2014-07-16 19:17:14 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-07-16 19:17:14 ----A---- C:\Windows\system32\vbscript.dll
2014-07-16 19:15:26 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-07-16 19:15:26 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-07-16 19:15:26 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-07-16 19:15:26 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-07-16 19:15:26 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-07-16 19:15:26 ----A---- C:\Windows\system32\msdrm.dll
2014-07-16 19:15:25 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-07-16 19:15:25 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-07-16 19:15:25 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-07-16 19:15:25 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-07-16 19:15:25 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-07-16 19:15:25 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-07-16 19:15:25 ----A---- C:\Windows\system32\secproc_isv.dll
2014-07-16 19:15:25 ----A---- C:\Windows\system32\secproc.dll
2014-07-16 19:15:25 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-07-16 19:15:25 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-07-16 19:15:25 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-07-16 19:15:25 ----A---- C:\Windows\system32\RMActivate.exe
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbport.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbohci.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbhub.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbehci.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbd.sys
2014-07-16 19:14:54 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2014-07-16 19:14:41 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2014-07-16 19:14:41 ----A---- C:\Windows\system32\msieftp.dll
2014-07-16 19:14:27 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2014-07-16 19:14:27 ----A---- C:\Windows\SYSWOW64\wmp.dll
2014-07-16 19:14:27 ----A---- C:\Windows\system32\wmploc.DLL
2014-07-16 19:14:27 ----A---- C:\Windows\system32\wmp.dll
2014-07-16 19:14:07 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-07-16 19:14:07 ----A---- C:\Windows\system32\tzres.dll
2014-07-16 19:13:49 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-07-16 19:13:49 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-07-16 19:13:49 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-07-16 19:13:49 ----A---- C:\Windows\system32\wscript.exe
2014-07-16 19:13:49 ----A---- C:\Windows\system32\scrrun.dll
2014-07-16 19:13:49 ----A---- C:\Windows\system32\cscript.exe
2014-07-16 19:13:40 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-07-16 19:13:40 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-07-16 19:13:32 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-07-16 19:13:32 ----A---- C:\Windows\system32\imagehlp.dll
2014-07-16 19:13:23 ----A---- C:\Windows\SYSWOW64\explorer.exe
2014-07-16 19:13:23 ----A---- C:\Windows\explorer.exe
2014-07-16 19:13:11 ----A---- C:\Windows\system32\spoolsv.exe
2014-07-16 19:13:11 ----A---- C:\Windows\splwow64.exe
2014-07-16 19:12:45 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2014-07-16 19:12:45 ----A---- C:\Windows\SYSWOW64\esent.dll
2014-07-16 19:12:45 ----A---- C:\Windows\system32\fsutil.exe
2014-07-16 19:12:45 ----A---- C:\Windows\system32\esent.dll
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\nvstor.sys
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\nvraid.sys
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\amdxata.sys
2014-07-16 19:12:45 ----A---- C:\Windows\system32\drivers\amdsata.sys
2014-07-16 19:06:52 ----D---- C:\Users\yourfragged\AppData\Roaming\ProductData
2014-07-16 11:52:58 ----D---- C:\ProgramData\Riot Games
2014-07-16 00:35:57 ----A---- C:\Windows\system32\nvspbridge64.dll
2014-07-16 00:35:56 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-07-16 00:35:25 ----D---- C:\Program Files (x86)\AGEIA Technologies
2014-07-16 00:26:53 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2014-07-16 00:26:53 ----A---- C:\Windows\system32\nvaudcap64v.dll
2014-07-16 00:26:53 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2014-07-16 00:26:49 ----A---- C:\Windows\system32\nvdispgenco6434043.dll
2014-07-16 00:26:49 ----A---- C:\Windows\system32\nvdispco6434043.dll
2014-07-16 00:26:48 ----A---- C:\Windows\system32\nvopencl.dll
2014-07-16 00:26:48 ----A---- C:\Windows\system32\NvFBC64.dll
2014-07-16 00:26:47 ----A---- C:\Windows\SYSWOW64\SET1DF4.tmp
2014-07-16 00:26:47 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2014-07-16 00:26:47 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2014-07-16 00:26:47 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2014-07-16 00:26:47 ----A---- C:\Windows\system32\NvIFR64.dll
2014-07-15 22:22:46 ----A---- C:\Windows\system32\drivers\atksgt.sys
2014-07-15 22:22:45 ----A---- C:\Windows\system32\drivers\lirsgt.sys
2014-06-25 00:47:09 ----A---- C:\Windows\_ HD PORNO _ Jewels Jade 02 ( brunetky anal mlib porno film brazzers teen best hardcore erotic porn oral nice ass young girls holky with old busty woman new akce sukani of girl milf xxx sex erot.lnk
2014-06-25 00:46:10 ----A---- C:\Windows\_ HD PORNO _ Nikita von James ( blondynky psp porno film brazzers teen best hardcore erotic porn oral nice ass young girls holky with old busty woman new akce sukani of girl milf xxx sex erotika.lnk
======List of files/folders modified in the last 1 month======
2014-07-19 15:19:32 ----D---- C:\Windows\Prefetch
2014-07-19 15:19:27 ----D---- C:\Windows\Temp
2014-07-19 15:19:22 ----RD---- C:\Program Files
2014-07-19 12:08:43 ----SHD---- C:\System Volume Information
2014-07-18 00:22:10 ----D---- C:\Windows\System32
2014-07-18 00:16:43 ----D---- C:\Windows\Tasks
2014-07-17 22:36:14 ----SHD---- C:\Windows\Installer
2014-07-17 22:35:36 ----D---- C:\Windows\system32\drivers
2014-07-17 22:07:19 ----D---- C:\Windows\system32\catroot
2014-07-17 22:07:11 ----D---- C:\Windows\inf
2014-07-17 22:07:05 ----D---- C:\Windows\system32\DriverStore
2014-07-17 22:06:12 ----D---- C:\Windows
2014-07-17 22:05:58 ----RD---- C:\Program Files (x86)
2014-07-17 22:05:58 ----HD---- C:\ProgramData
2014-07-17 22:04:29 ----D---- C:\ProgramData\Package Cache
2014-07-17 22:04:25 ----D---- C:\Windows\SysWOW64
2014-07-17 21:52:40 ----D---- C:\ProgramData\Razer
2014-07-17 21:52:40 ----D---- C:\Program Files (x86)\Razer
2014-07-17 21:51:37 ----D---- C:\Program Files (x86)\IObit
2014-07-17 21:22:12 ----D---- C:\ProgramData\ccoonntoinuUEtossavea
2014-07-17 19:11:48 ----D---- C:\Windows\system32\config
2014-07-17 15:41:21 ----D---- C:\Windows\Help
2014-07-17 15:15:51 ----D---- C:\Windows\system32\catroot2
2014-07-17 14:48:59 ----D---- C:\Windows\system32\wfp
2014-07-17 14:48:57 ----D---- C:\Windows\system32\wbem
2014-07-17 14:47:59 ----D---- C:\Windows\system32\NDF
2014-07-17 14:47:58 ----D---- C:\Windows\system32\CodeIntegrity
2014-07-17 14:47:58 ----D---- C:\Windows\security
2014-07-17 14:47:58 ----D---- C:\Progamy
2014-07-17 14:47:54 ----D---- C:\Windows\registration
2014-07-17 14:47:04 ----RD---- C:\Users
2014-07-16 23:05:32 ----D---- C:\Windows\Microsoft.NET
2014-07-16 23:05:02 ----RSD---- C:\Windows\assembly
2014-07-16 22:14:42 ----D---- C:\Game
2014-07-16 22:03:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-16 21:49:49 ----D---- C:\Windows\winsxs
2014-07-16 21:35:59 ----D---- C:\Windows\SYSWOW64\Dism
2014-07-16 21:35:59 ----D---- C:\Windows\system32\Dism
2014-07-16 21:35:59 ----D---- C:\Windows\system32\cs-CZ
2014-07-16 21:35:58 ----D---- C:\Windows\SYSWOW64\migration
2014-07-16 21:35:58 ----D---- C:\Windows\system32\migration
2014-07-16 21:35:58 ----D---- C:\Program Files\Internet Explorer
2014-07-16 21:35:58 ----D---- C:\Program Files (x86)\Internet Explorer
2014-07-16 21:35:57 ----D---- C:\Windows\ehome
2014-07-16 21:35:57 ----D---- C:\Program Files\Windows Journal
2014-07-16 21:35:53 ----D---- C:\Windows\PolicyDefinitions
2014-07-16 21:35:52 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-07-16 21:35:51 ----D---- C:\Windows\AppPatch
2014-07-16 21:35:49 ----D---- C:\Program Files\Windows Media Player
2014-07-16 21:35:49 ----D---- C:\Program Files (x86)\Windows Media Player
2014-07-16 19:16:45 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-07-16 19:11:25 ----D---- C:\Windows\Logs
2014-07-16 19:11:24 ----D---- C:\Users\yourfragged\AppData\Roaming\DAEMON Tools Lite
2014-07-16 19:07:31 ----D---- C:\Users\yourfragged\AppData\Roaming\uTorrent
2014-07-16 19:02:07 ----D---- C:\Programy
2014-07-16 19:00:13 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-07-15 22:01:18 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2014-07-17 458336]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2013-05-22 17720]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-04-07 283200]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2014-07-17 625248]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2013-10-20 29792]
R1 klpd;klpd; C:\Windows\system32\DRIVERS\klpd.sys [2013-04-12 15456]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2013-05-14 55904]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2014-07-17 178272]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2014-07-15 43168]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\Windows\system32\DRIVERS\stflt.sys [2014-07-17 51496]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-12-30 3760344]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2014-07-17 29280]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2013-10-20 29280]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-03-31 40392]
R3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver; C:\Windows\system32\DRIVERS\Rtnic64.sys [2009-06-10 51712]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-11-20 883928]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2014-07-15 310728]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Progamy\Garena Plus\Room\safedrv.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 Razerlow;Razer Pro|Solutions; C:\Windows\system32\drivers\Razerlow.sys [2013-11-20 11136]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2013-11-19 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2013-11-19 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-11-19 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2013-11-19 30208]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S4 klflt;klflt; C:\Windows\system32\DRIVERS\klflt.sys [2014-07-17 115296]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AVP;Služba Kaspersky Anti-Virus; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [2013-10-20 214512]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-10-15 1640768]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2014-05-14 1146304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2014-05-04 2152736]
S2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe []
S2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-11-19 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-07 116648]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-07 116648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------